
jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:
next up, handlers on the server-side to minimally re-validate & drop into PENDING database (for 2FA).
I will continue to leave the 2FA one-time-key handler (to make it move from PENDING to REAL_LIVE_USERS) *not* wired in until these seem adequate. next up after CREATE/UPDATE/DEACTIVATE: an “I forgot my password” handler.